You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Dec 1, 2020. It is now read-only.
WS-2018-0209 - Medium Severity Vulnerability
HTTP request logger middleware for node.js
Library home page: https://registry.npmjs.org/morgan/-/morgan-1.9.0.tgz
Path to dependency file: /instabyte/package.json
Path to vulnerable library: /tmp/git/instabyte/node_modules/morgan/package.json
Dependency Hierarchy:
Morgan before 1.9.1 is vulnerable to code injection when user input is allowed into the filter or combined with a prototype pollution attack.
Publish Date: 2018-11-25
URL: WS-2018-0209
Base Score Metrics not available
Type: Upgrade version
Origin: https://www.npmjs.com/advisories/735
Release Date: 2019-04-08
Fix Resolution: 1.9.1
Step up your Open Source Security Game with WhiteSource here